event_list = ['010100', '010200', '010300', '010401', '010402', '010403', '010501', '010502', '010503', '010504',
              '010601', '010602', '010603', '010701', '010702', '010703', '010704', '010705', '010706', '010707',
              '010709', '010710', '010801', '011003', '011101', '011102', '011103', '011104', '011201', '011202',
              '010802', '010803', '010804', '010708', '011203', '011204', '011301', '011302', '011303', '011304',
              '010805', '010901', '010902', '010903', '010904', '010905', '010906', '010907', '010908',
              '010909', '011001', '011002', '011305', '011306', '011401', '011402', '011403', '011500', '011600']

td_host_control_event_fields = ['event_id', 'rule_id', 'device_id', 'found_time', 'src_ip', 'src_port', 'dst_ip',
                                'dst_port', 'm_id', 'affect_resource', 'rule_desc', 'payload_length',
                                'rule_desc_packets', 'proto', 'app_proto', 'user_agent', 'content_type', 'url',
                                'payload', 'src_ip_type', 'dst_ip_type', 'rule_segment', 'ul_traffic', 'dl_traffic',
                                'ul_packtes', 'dl_packtes', 'detail_info', 'malware_sha1', 'malware_sha256',
                                'malware_md5', 'data_sources', 'platform', 'rat', 'imei', 'terminal_type', 'apn',
                                'malware_name', 'reason', 'vulnerability_type', 'imsi', 'msisdn', 'tac', 'cell_id',
                                'family_name', 'organization_position']

td_network_attack_event_fields = ['event_id', 'rule_id', 'found_time', 'src_ip_type', 'dst_ip_type', 'src_ip', 'dst_ip',
                                  'src_port', 'dst_port', 'organization_position', 'ul_traffic', 'dl_traffic',
                                  'ul_packtes', 'dl_packtes', 'payload', 'rule_desc_packets', 'device_id', 'proto',
                                  'app_proto', 'user_agent', 'content_type', 'url', 'payload_length', 'rule_segment',
                                  'detail_info', 'device_ip', 'malware_sha1', 'malware_sha256', 'malware_md5',
                                  'data_sources', 'platform', 'rat', 'imei', 'terminal_type', 'apn', 'imsi', 'msisdn',
                                  'tac', 'cell_id', 'family_name', 'disposition_result', 'disposition_measure']

td_harm_program_event_fields = ['event_id', 'rule_id', 'device_id', 'virus_behavior', 'found_time', 'virus_name',
                                'malware_name', 'malware_sample', 'malware_sha1', 'malware_md5', 'dst_ip_type',
                                'dst_ip', 'dst_port', 'src_ip_type', 'src_ip', 'src_port', 'request_url', 'remarks',
                                'rule_desc_packets', 'file_len', 'user_agent', 'content_type', 'app_proto',
                                'protocol_type', 'rule_segment', 'ul_traffic', 'dl_traffic', 'ul_packtes', 'dl_packtes',
                                'detail_info', 'device_ip', 'malware_sha256', 'data_sources', 'platform', 'rat', 'imei',
                                'terminal_type', 'apn', 'imsi', 'msisdn', 'tac', 'cell_id', 'organization_position',
                                'm_id', 'affect_resource', 'app_name', 'app_url', 'os_version', 'network_behavior',
                                'event_detail']

td_text_transmission_event_fields = ['rat', 'imei', 'terminal_type', 'apn', 'imsi', 'msisdn', 'tac', 'cell_id',
                                     'event_time', 'duration', 'rule_version', 'flowid', 'msg_type', 'rule_source',
                                     'rule_id', 'action', 'ctrl_type', 'redirect_url', 'protocol',
                                     'application_protocol', 'ip_type', 'src_ip', 'src_port', 'dst_ip', 'dst_port',
                                     'ul_traffic', 'dl_traffic', 'ul_packets', 'dl_packets', 'is_pcap', 'rcode',
                                     'file_name', 'file_len', 'file_md5', 'content_length', 'http_cmd',
                                     'content_type', 'user_agent', 'url', 'refer',
                                     'json_exports', 'payload', 'detail_json', 'device_id']

td_shezha_ip_fields = ['command_id', 'type', 'seq_number', 'ip_type', 'dst_ip', 'original_type', 'mark_num',
                       'original_type_extend', 'lastest_found_time', 'info_type2', 'fake_category',
                       'fake_target', 'fraud_type']

td_block_log_reported_fields = ['msg_id', 'dispose_type', 'disposition_result', 'reason', 'type', 'ip_type', 'src_ip',
                                'dest_ip', 'src_port', 'dest_port', 'url', 'rule_id', 'handle_flag', 'handle_content',
                                'domain', 'protocol', 'application_protocol', 'gather_time', 'redirect_url']

td_iot_communication_event_fields = ['version', 'od_id', 'command_id', 'effect_system', 'rule_id', 'device_id',
                                     'device_vender', 'device_type', 'device_version', 'src_ip_type', 'dst_ip_type',
                                     'src_ip', 'src_port', 'dst_ip', 'dst_port', 'ul_traffic', 'dl_traffic',
                                     'ul_packtes', 'dl_packets', 'is_device', 'asset', 'proto', 'app_proto', 'url',
                                     'platform',
                                     'user_type', 'user_name', 'rule_desc', 'start_time', 'end_time', 'rat', 'imei',
                                     'terminal_type', 'terminal_industry', 'apn', 'access_flow_provicen', 'iot_base',
                                     'remarks', 'imsi', 'msisdn', 'tac', 'cell_id']

td_shezha_app_monitor_detail_reported_fields = ['command_id', 'mould_id', 'company', 'area', 'src_ip_type', 'src_ip',
                                                'src_port', 'src_ip_province', 'domain', 'url', 'protocol_type',
                                                'application_protocol', 'access_time', 'time_len', 'file_name',
                                                'malware_sample', 'malware_sample_file_path', 'malware_sha1',
                                                'malware_md5', 'file_len', 'direction', 'file_type', 'content_type',
                                                'remarks', 'app_name', 'app_version', 'pkg_name', 'signature',
                                                'sign_sha1', 'sign_sha256', 'description']
